Skip to main content
FRAMEWORK

Map your AI management system.

ISO/IEC 42001 is the first management system standard for AI that an organization can be certified against. It follows the same harmonized structure as ISO 27001 — context, leadership, planning, support, operation, evaluation, improvement — and applies it to the development, provision and use of AI systems. Annex A holds the AI-specific controls. Like 27001, you are audited against the clauses and sampled against the controls.

Which means it inherits the same operating problem 27001 has, plus one of its own. The familiar problem is that a management system has to keep running after the certification project ends. The new one is that the thing being managed — the AI systems you actually use — is the least well inventoried asset class most organizations hold. A management system wrapped around an incomplete inventory manages the wrong thing very thoroughly.

Who it applies to

Organizations that develop, provide or use AI systems — and the standard is explicit that using counts. A company with no AI product and no data-science team can still be in scope the moment it runs a vendor's model on customer data. Like 27001, it arrives when someone asks: a customer, a procurement gate, or a regulator who accepts it as evidence of an organized approach to AI risk.

One inventory, three regimes

42001 does not stand alone. The EU AI Act imposes legal duties on providers and deployers of AI systems; the NIST AI RMF offers voluntary structure for the same risk; ISO 23894 provides the risk-management guidance that feeds 42001 the way 27005 feeds 27001. All of them ask about the same systems. Held as three inventories, they disagree within a quarter. Held as one — purpose, owner, risk classification, assessments and evidence per system — each regime reads its own view of the same record, and a change to a system changes every answer at once. That is the difference between a management system and three spreadsheets.

What it asks, in operating terms

Read as an operating requirement rather than a standard document, 42001 reduces to a handful of standing asks — each answerable from live state, not reconstructed before a Stage 2 audit.

ISO 42001 requirements · how TruSecure answers them
What the standard asksWhere it is answered
Know every AI system in scope, and what it is forAI system inventory · shared with the AI Act and AI RMF
Run an AI management system, not a projectGovernance workspace · policy, owners, review dates
Assess AI risk and impact, on a repeating cycleRisk register · 23894-shaped, treatment tracked to closure
Declare which Annex A controls apply, and why notStatement of Applicability · generated from live control state
Show the controls operated, with a named human accountableEvidence automation · continuous, owner per system
Give the certification body what it samples, quicklyAuditor export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the system, the evidence and the person behind it. This excerpt is what an AI management system file is made of:

AIMS file · excerptSample data
Systems in scope
12 · 4 vendor-embedded
Shared with
EU AI Act · NIST AI RMF · ISO 23894
Statement of Applicability
generated · current as of today
Open nonconformities
1 · owned, closes before surveillance
Auditor export
sealed · sha256:b8d1...0e6f

Where teams usually start

With a demo walked through by TruSecure — the AI systems you already run pulled into one inventory, a Statement of Applicability generated in front of you, the same record answering 42001, the AI Act and AI RMF. The certificate itself comes from an accredited certification body; TruSecure prepares and maintains the evidence, and holds no certification of its own yet. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

ISO/IEC 42001 is the first certifiable management system standard for organizations that develop, provide, or use AI systems. TruSecure maintains one AI system inventory shared across ISO 42001, the EU AI Act, and NIST AI RMF mapping.